diff options
| author | Roman Arutyunyan <arut@nginx.com> | 2026-04-08 17:19:24 +0400 |
|---|---|---|
| committer | Roman Arutyunyan <arutyunyan.roman@gmail.com> | 2026-04-14 09:53:13 +0400 |
| commit | d3a76322cf7abedb32b8216d1e5c0cef4858e4d4 (patch) | |
| tree | a3efc33a7486dae0450ce0ebf7f05c0b833565e9 /src/http/modules | |
| parent | 00979ba9d843be266529067285b635070f2d1993 (diff) | |
| download | nginx-d3a76322cf7abedb32b8216d1e5c0cef4858e4d4.tar.gz nginx-d3a76322cf7abedb32b8216d1e5c0cef4858e4d4.tar.bz2 | |
Restrict connection-specific headers in HTTP/2 and HTTP/3
As per RFC 9113 and RFC 9114, any message containing such headers MUST be
treated as malformed.
As per RFC 9110, Section 7.6.1, the following headers are considered
connection-specific:
- Connection
- Proxy-Connection
- Keep-Alive
- TE
- Transfer-Encoding
- Upgrade
The only exception is the TE header field, which MAY be present in a
request header, but it MUST NOT contain any value other than "trailers".
Diffstat (limited to 'src/http/modules')
0 files changed, 0 insertions, 0 deletions
